RememberSAFE
Claude Code plugin that generates individualized knowledge systems from conversation. You describe how you think and work, have a conversation and get a complete second brain as markdown files you own.
Overview
Claude Code plugin that generates individualized knowledge systems from conversation. You describe how you think and work, have a conversation and get a complete second brain as markdown files you own.
9eccf964e924OBSERVED · 2026-10-07What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: remember description: Capture friction as methodology notes. Three modes — explicit description, contextual (review recent corrections), session mining (scan transcripts for patterns). Triggers on "/remember", "/remember [description]". version: "1.0" generated_from: "arscontexta-v1.6" user-invocable: true context: fork model: sonnet allowed-tools: Read, Write, Edit, Grep, Glob, Bash --- ## Runtime Configuration (Step 0 — before any processing) Read these files to configure domain-specific behavior: 1. **`ops/derivation-manifest.md`** — vocabulary mapping, domain context - Use `vocabulary.notes` for the notes folder name - Use `vocabulary.note` for the note type name in output - Use `vocabulary.rethink` for rethink command name in threshold alerts - Use `vocabulary.topic_map` for MOC references 2. **`ops/config.yaml`** — thresholds - `self_evolution.observation_threshold` (default: 10) — for threshold alerts - `self_evolution.tension_threshold` (default: 5) — for threshold alerts 3. **`ops/methodology/`** — read existing methodology notes before creating new ones (prevents duplicates) If these files don't exist (pre-init invocation or standalone use), use universal defaults. ## EXECUTE NOW **Target: $ARGUMENTS** Parse immediately: - If target contains a quoted description or unquoted text: **explicit mode** — user describes friction directly - If target is empty: **contextual mode** — review recent conversation for corrections - If target contains `--mine-sessions` or `--mine`: **session mining mode** — scan ops/sessions/ for patterns **START NOW.** Reference below defines the three modes. --- ## Explicit Mode User provides a description: `/remember "don't process personal notes like research"` or `/remember always check for duplicates before creating` ### Step 1: Parse the Friction Analyze the user's description to extract: - **What the agent did wrong** (or what the user wants to prevent) - **What the user wants instead** (the correct behavior) - **The scope** — when does this apply? Always? Only for specific content types? Only in certain phases? - **The category** — which area of agent behavior does this affect? | Category | Applies When | |----------|-------------| | processing | How to extract, reduce, or handle content | | capture | How to record, file, or organize incoming material | | connection | How to find, evaluate, or add links between notes | | maintenance | How to handle health checks, reweaving, cleanup | | voice | How to write, what tone or style to use | | behavior | General agent conduct, interaction patterns | | quality | Standards for notes, descriptions, titles | ### Step 2: Check for Existing Methodology Notes Before creating a new note, read all files in `ops/methodology/`: ```bash ls -1 ops/methodology/*.md 2>/dev/null ``` For each existing note, check if it covers the same behavioral area. Specifically: - Does an existing note address the same friction? - Would the new learning extend an existing note rather than warrant a new one? | Check Result | Action | |-------------|--------| | No existing notes in this area | Create new methodology note | | Existing note covers different aspect of same area | Create new note, link to existing | | Existing note covers same friction | Extend existing note with new evidence instead of creating duplicate | | Existing note contradicts new friction | Create both a new methodology note AND an observation about the contradiction | ### Step 3: Create Methodology Note Write to `ops/methodology/`: **Rule Zero:** This methodology note becomes part of the system's canonical specification. ops/methodology/ is not a log of what happened — it is the authoritative declaration of how the system should behave. Write this note as a directive: what the agent SHOULD do, not what went wrong. Future sessions, /rethink drift checks, and meta-skills will consult this note as ground truth for system behavior. **Filename:** Convert the prose title to kebab-case. Example: "don't process personal notes like research" becomes `dont-process-personal-notes-like-research.md`. ```markdown --- description: [what this methodology note teaches — specific enough to be actionable] type: methodology category: [processing | capture | connection | maintenance | voice | behavior | quality] source: explicit created: YYYY-MM-DD status: active --- # [prose-as-title describing the learned behavior] ## What to Do [Clear, specific guidance. Not "be careful" but "when encountering X, do Y instead of Z."] ## What to Avoid [The specific anti-pattern this note prevents. What was the agent doing wrong?] ## Why This Matters [What goes wrong without this guidance. Connect to the user's actual friction — what broke, what was confusing, what wasted time.] ## Scope [When does this apply? Always? Only for certain content types? Only during specific phases? Be explicit about boundaries.] --- Related: [[methodology]] ``` **Writing quality for methodology notes:** - Be specific enough that a fresh agent session could follow this guidance without additional context - Use concrete examples where possible — "when processing therapy notes" not "when processing certain types of content" - State both the DO and the DON'T — methodology notes that only say what to do miss the anti-pattern that triggered them - Keep scope explicit — unbounded methodology notes get applied where they should not be ### Step 4: Update Methodology MOC Edit `ops/methodology.md` (create if missing): 1. Find the section for the note's category 2. Add the note with a context phrase: `- [[note title]] — [what this teaches]` 3. If no section exists for this category, create one ```markdown ## [Category] - [[existing note]] — what it teaches - [[new note]] — what this teaches ``` ### Step 5: Check Pattern Threshold Count methodology notes in the same category: ```bash grep -rl "^category: [CATEGORY]" ops/methodology/ 2>/dev/null | wc -l | tr -d '
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
9eccf964e924full audit observations/trust-audit/skill/agenticnotetaking__remember.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 9eccf964e924 | SAFE | B | 89 | first audit |
Questions
What does the Remember skill do?
Claude Code plugin that generates individualized knowledge systems from conversation. You describe how you think and work, have a conversation and get a complete second brain as markdown files you own.
Is Remember safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Remember access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (9eccf964e924), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.